LEGAL REFERENCE

How 666bat Handles Your Personal Data

Your privacy matters to us, and this policy explains exactly what personal information 666bat collects when you open or use your account, how we store it securely, and...

Data encrypted at restAccount access logs retained 12 monthsNo third-party data salesPakistani payment data isolatedRight to request deletion
666bat How 666bat Handles Your Personal Data

What This Privacy Policy Covers and Why

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

PRIVACY CONTACT PATHS

Reach Us About Your Data Rights

If you have questions about this policy, want to update your stored information, or wish to submit a data deletion request, our support team handles privacy queries through three channels with response times measured in hours, not days.

Team online

Live Chat

Our live chat channel connects you to a privacy-aware support agent around the clock. Start a conversation from your account dashboard and reference 'data request' so your query is routed correctly within minutes.

Email Support

Send your privacy request to our dedicated support address. Include your registered account details and the specific action you want taken — correction, export or deletion — and we aim to respond within 24 hours.

Account Portal

Log into your 666bat account portal to review the personal details we currently hold, update your contact information directly, or submit a formal data access request without needing to contact an agent.

HOW WE PROTECT YOUR ACCOUNT

Six Practices That Keep Your Data Safe

We designed our data-handling practices around the reality that Pakistani account holders use mobile-first payment rails. Each of the following measures applies from the moment you submit your first JazzCash or Easypaisa...

TLS Encryption in Transit

Every data exchange between your device and 666bat servers travels over TLS 1.2 or higher. This covers account logins, payment submissions via JazzCash or Easypaisa, and any form you complete on the site.

Encrypted Storage at Rest

Personal details, KYC documents, and payment references stored on our servers are encrypted at rest using AES-256. Decryption keys are held separately and rotated on a defined schedule.

Access Logging

Every time your account is accessed — whether by you or by a support agent acting on a verified request — an access log entry is created. You can request your access log as part of a data export.

Payment Data Isolation

Transaction references from JazzCash, Easypaisa, SadaPay and Raast are stored in isolated tables with separate access controls, reducing the surface area for any single point of exposure.

Session Token Expiry

Active session tokens expire automatically after a defined period of inactivity. This limits the window during which an unattended device could expose your account to unauthorised access.

Staff Data Access Controls

Our team members access personal data only on a need-to-know basis tied to a specific support function. Access is logged, reviewed periodically, and revoked immediately when a role changes.

How This Policy Aligns With Our Other Terms

Our privacy commitments are consistent across every part of the 666bat platform. The table below shows how this policy connects to related documents so you can see the...

Terms and ConditionsOur general terms define the account relationship; this privacy policy defines the data relationship. Both documents apply simultaneously when you hold an active 666bat account.
Cookie PolicyOur cookie policy covers browser and device identifiers specifically. This privacy policy covers all other personal data including payment details and KYC documents.
Withdrawal TermsWithdrawal terms govern timing and method. This policy governs the personal data — including SadaPay and Raast identifiers — created during that withdrawal process.
Account VerificationKYC checks are described in account verification terms. This policy explains how the documents you submit during that process are stored, retained and eventually deleted.
Marketing CommunicationsIf you opt into promotional communications, our email and SMS preferences page governs frequency. This policy explains what contact data we hold to deliver those communications.
Third-Party IntegrationsWhere we use third-party processors to route JazzCash or Easypaisa payments, those processors operate under data-processing agreements that require them to meet the same standards described here.
Data Retention ScheduleOur retention schedule sets the specific periods for each data category. This policy summarises those periods; the full schedule is available on request from our support team.

Six Elements That Shape This Policy

Rather than a wall of legal text, we have structured this policy around six concrete commitments. Each one maps to a real aspect of how your...

Collection Scope

We collect only what we need to run your account — name, contact details, payment references and device identifiers. No speculative data collection, no profiling for third-party advertising, and no sharing without a lawful basis.

Storage Duration

Account data is held for the period your account is active plus the statutory retention period required under applicable local regulations. Once that window closes, data is deleted or anonymised on a documented schedule.

Your Access Rights

You may request a full export of the personal data we hold on you at any time. Requests are processed within the timeframe specified in this policy and fulfilled at no charge through your account portal or via email.

Correction and Deletion

If any detail we hold is inaccurate, you can correct it directly in your account portal. Deletion requests for data no longer required for legal or operational purposes are processed within 30 days of verification.

Security Architecture

Our privacy commitments are backed by technical controls — encryption, access logging and session management — described in the trust section of this policy. Commitments without controls are not commitments worth making.

Policy Update Process

When this policy changes materially, we notify account holders via the registered contact method before the change takes effect, giving you time to review the update before it applies to your account.

Answers to Your Privacy Policy Questions

We collect your name, date of birth, email address, phone number, and payment method identifiers such as your JazzCash or Easypaisa mobile number. Device and session data is also collected automatically when you log in.

We share data only with payment processors needed to route JazzCash, Easypaisa, SadaPay and Raast transactions, and with regulatory bodies when required by law. We do not sell your data to advertisers or data brokers under any circumstance.

We retain account data for the duration your account is active and for the statutory period following closure, as required by applicable law in supported regions. Payment references are kept for the period mandated by financial regulations.

Log into your account portal and submit a data access request, or email our support team with your account details and the words 'data export request' in the subject line. We process requests within the timeframe set out in this policy.

Yes. Once your account is closed and any legally required retention period has passed, we will delete or anonymise your personal data on request. Submit your deletion request through the account portal or via our support email.

Payment references from JazzCash, Easypaisa, SadaPay and Raast are stored in isolated, encrypted tables with restricted access controls. Data in transit is protected by TLS encryption and never logged in plain text on our systems.

Yes. If we make a material change to this policy, we will notify you via your registered contact method before the update takes effect. Minor clarifications may be made without notice, but the effective date at the top of the policy will always reflect the latest version.